PLATFORM

Security & Compliance

Security is built into how we design, deploy, and operate AI agents — scoped permissions, approval gates, complete audit trails, and certified cloud and payment platforms underneath.

SECURITY PRINCIPLES

Built with security as a foundation

Every layer of our platform is designed with security, privacy, and compliance in mind.

Defense in Depth

Multiple layers of security controls from infrastructure to application level.

Complete Visibility

Full audit logs of all AI agent actions, data access, and system changes.

Data Encryption

Data encrypted in transit and at rest using industry-standard encryption.

Certified Platforms

Deployed on cloud providers with SOC 2 Type II and ISO 27001 attestations. Payments stay on Shopify's PCI DSS Level 1 checkout.

DATA PROTECTION

Your data is protected at every layer

Comprehensive data protection measures from collection to deletion.

Encryption at Rest

Data encrypted at rest using our cloud providers' managed encryption.

Encryption in Transit

HTTPS/TLS for all traffic between services and clients.

Access Controls

Role-based access control (RBAC) with principle of least privilege.

Data Isolation

Customer data logically isolated with strict separation between tenants.

No Card Data

Agents never handle payment card details. Checkout is handed off to Shopify.

Data Retention

Retention limits agreed per engagement, with data deletion on request.

AI GOVERNANCE

Controlled and observable AI execution

Our governance model makes AI agents safe for production commerce operations.

Scoped Permissions

AI agents operate with explicitly defined permissions. No agent can access data or perform actions outside its scope.

Audit Trails

Complete logs of all AI decisions, actions taken, data accessed, and reasoning used. Searchable and exportable.

Approval Gates

High-risk actions require human approval. Define which operations need review before execution.

Evaluation Before Production

All agents tested against evaluation scenarios before deployment. No untested AI in production.

COMPLIANCE

Clear about what's certified, and by whom

We build on certified cloud and payment platforms, and we're explicit about which certifications belong to which provider.

Handled by Shopify

PCI DSS

Card data never touches our agents. Checkout is handed off to Shopify, a PCI DSS Level 1 certified service provider.

DPA on request

GDPR

We support your obligations as data controller: data minimisation, agreed retention limits, and deletion on request.

Cloud provider attested

SOC 2 Type II & ISO 27001

Agents run on major cloud providers — AWS, Google Cloud, Azure, or Vercel — that hold these attestations. They cover our cloud providers, not Gwiksoft as a company.

Per engagement

Your security requirements

We work within your security policies and access rules, and answer vendor security reviews as part of every engagement.

Running a vendor security review or need a DPA? security@gwiksoft.com

INFRASTRUCTURE SECURITY

Secure from the ground up

The controls in place across infrastructure, access, and data.

Infrastructure

  • Hosted on cloud providers with SOC 2 Type II and ISO 27001 attestations
  • Data encrypted at rest with provider-managed encryption
  • HTTPS/TLS for all traffic in transit

Access

  • Multi-factor authentication required on all admin accounts
  • Least-privilege access for people and agents
  • Scoped credentials for each system integration

Payments & Personal Data

  • No card data handled by agents — checkout stays in Shopify
  • Retention limits and deletion on request
  • Data Processing Agreement available on request

INCIDENT RESPONSE

Prepared for security events

Clear commitments for handling security incidents and keeping affected clients informed.

If something goes wrong

  • 1
    Containment and remediation are the first priority
  • 2
    Affected clients notified without undue delay
  • 3
    Credentials and access rotated where needed
  • 4
    Post-incident review shared with affected clients

Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to:

security@gwiksoft.com

  • • We'll acknowledge within 24 hours
  • • We'll provide updates on remediation
  • • We'll credit researchers (if desired)
  • • We don't currently offer bug bounties

Security questions?

For security questions, vendor security reviews, DPA requests, or to report a vulnerability, contact our security team.

Response time: < 24 hours for security issues · < 72 hours for general inquiries